ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareAmadey

Amadey has collected the computer name and OS version from a compromised machine.

T1082
System Information Discovery
MalwareProxysvc

Proxysvc collects the OS version, country name, MAC address, computer name, and physical memory statistics.

T1082
System Information Discovery
MalwareOrz

Orz can gather the victim OS version and whether it is 64 or 32 bit.

T1082
System Information Discovery
MalwareNOKKI

NOKKI can gather information on the operating system on the victim’s machine.

T1082
System Information Discovery
Malwareyty

yty gathers the computer name, CPU information, Microsoft Windows version, and runs the command systeminfo.

T1082
System Information Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about the OS and computer name.

T1082
System Information Discovery
MalwareStuxnet

Stuxnet collects system information including computer and domain names, OS version, and S7P paths.

T1082
System Information Discovery
MalwareIronWind

IronWind can capture the OS version and computer name of the compromised host.

T1082
System Information Discovery
MalwareRotaJakiro

RotaJakiro executes a set of commands to collect device information, including `uname`. Another example is the `cat /etc/*release | uniq` command used to collect the current OS distribution.

T1082
System Information Discovery
MalwareGet2

Get2 has the ability to identify the computer name and Windows version of an infected host.

T1082
System Information Discovery
MalwarePOWRUNER

POWRUNER may collect information about the system by running hostname and systeminfo on a victim.

T1082
System Information Discovery
MalwareSharpStage

SharpStage has checked the system settings to see if Arabic is the configured language.

T1082
System Information Discovery
MalwareSardonic

Sardonic has the ability to collect the computer name, and CPU manufacturer name from a compromised machine. Sardonic also has the ability to execute the `ver` and `systeminfo` commands.

T1082
System Information Discovery
MalwareHALFBAKED

HALFBAKED can obtain information about the OS, processor, and BIOS.

T1082
System Information Discovery
MalwareMisdat

The initial beacon packet for Misdat contains the operating system version of the victim.

T1082
System Information Discovery
MalwareEmissary

Emissary has the capability to execute ver and systeminfo commands.

T1082
System Information Discovery
MalwareKEYMARBLE

KEYMARBLE has the capability to collect the computer name, language settings, the OS version, CPU information, and time elapsed since system start.

T1082
System Information Discovery
MalwareBUBBLEWRAP

BUBBLEWRAP collects system information, including the operating system version and hostname.

T1082
System Information Discovery
MalwareHAWKBALL

HAWKBALL can collect the OS version, architecture information, and computer name.

T1082
System Information Discovery
MalwareUrsnif

Ursnif has used Systeminfo to gather system information.

T1082
System Information Discovery
MalwareThreatNeedle

ThreatNeedle can collect system profile information from a compromised host.

T1082
System Information Discovery
MalwareRansomHub

RansomHub can retrieve information about virtual machines.

T1082
System Information Discovery
MalwareZLib

ZLib has the ability to enumerate system information.

T1082
System Information Discovery
MalwareRedLeaves

RedLeaves can gather extended system information including the hostname, OS version number, platform, memory information, time elapsed since system startup, and CPU information.

T1082
System Information Discovery
MalwareTsundere Botnet

Tsundere Botnet has collected the machine’s MAC address, total memory, GPU information and other system information.

T1082
System Information Discovery
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can check the type of Ivanti VPN device it is running on by executing `first_run()` to identify the first four bytes of the motherboard serial number.

T1082
System Information Discovery
MalwareFelismus

Felismus collects the system information, including hostname and OS version, and sends it to the C2 server.

T1082
System Information Discovery
MalwareZeus Panda

Zeus Panda collects the OS version, system architecture, computer name, product ID, install date, and information on the keyboard mapping to determine the language used on the system.

T1082
System Information Discovery
MalwareHavoc

Havoc can gather system information including hostname, domain, and OS details.

T1082
System Information Discovery
MalwareCARROTBAT

CARROTBAT has the ability to determine the operating system of the compromised host and whether Windows is being run with x86 or x64 architecture.

T1082
System Information Discovery
MalwareGravityRAT

GravityRAT collects the MAC address, computer name, and CPU information.

T1082
System Information Discovery
MalwareInvisibleFerret

InvisibleFerret has collected OS type, hostname and system version through the "pay" module. InvisibleFerret has also queried the victim device using Python scripts to obtain the User and Hostname.

T1082
System Information Discovery
MalwareBankshot

Bankshot gathers system information, network addresses, and the operation system version.

T1082
System Information Discovery
MalwareHAPPYWORK

can collect system information, including computer name, system manufacturer, IsDebuggerPresent state, and execution path.

T1082
System Information Discovery
MalwarePLAINTEE

PLAINTEE collects general system enumeration data about the infected machine and checks the OS version.

T1082
System Information Discovery
MalwarePony

Pony has collected the Service Pack, language, and region information to send to the C2.

T1082
System Information Discovery
MalwareWinMM

WinMM collects the system name, OS version including service pack, and system install date and sends the information to the C2 server.

T1082
System Information Discovery
MalwareTONESHELL

TONESHELL has the ability to retrieve the name of the infected machine.

T1082
System Information Discovery
MalwareKasidet

Kasidet has the ability to obtain a victim's system name and operating system version.

T1082
System Information Discovery
MalwareOceanSalt

OceanSalt can collect the computer name from the system.

T1082
System Information Discovery
MalwareBrave Prince

Brave Prince collects hard drive content and system configuration information.

T1082
System Information Discovery
MalwareMedusa Ransomware

Medusa Ransomware has collected data from the SMBIOS firmware table using `GetSystemFirmwareTable`.

T1082
System Information Discovery
MalwareAppleSeed

AppleSeed can identify the OS version of a targeted system.

T1082
System Information Discovery
MalwaremacOS.OSAMiner

macOS.OSAMiner can gather the device serial number.

T1082
System Information Discovery
MalwareNETWIRE

NETWIRE can discover and collect victim system information.

T1082
System Information Discovery
MalwareEnvyScout

EnvyScout can determine whether the ISO payload was received by a Windows or iOS device.

T1082
System Information Discovery
MalwareSslMM

SslMM sends information to its hard-coded C2, including OS version, service pack information, processor speed, system name, and OS install date.

T1082
System Information Discovery
MalwareIMAPLoader

IMAPLoader uses WMI queries to gather information about the victim machine.

T1082
System Information Discovery
MalwareGomir

Gomir collects information on infected systems such as hostname, username, CPU, and RAM information.

T1082
System Information Discovery
MalwareAria-body

Aria-body has the ability to identify the hostname, computer name, Windows version, processor speed, and machine GUID on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.